Changelog

New tools and meaningful updates. Follow via RSS.

Answering the questions people actually search for

2026-09-10

A content pass driven by search data rather than new tools.

Intune network endpoints now covers Entra join and hybrid join device registration, the TPM attestation hosts that Autopilot self-deploying and pre-provisioning modes need, the NCSI probe, and a questions section: the minimum port set, whether the endpoints differ by region (they don't), proxy and TLS inspection rules, IPv6, and the Network List Manager TLS endpoint.

Error database — a new entry for the WLAN-AutoConfig Explicit EAP failure received message; the NPS reason 65 entry gains the policy-side fix (Ignore user account dial-in properties) and covers computer accounts and the unset attribute case; the Autopilot Registering your device for mobile management entry covers pre-provisioning and OEM-specific TPM attestation failures; AADSTS50126 explains the trace and correlation IDs.

Private endpoint DNS zones — API Management added to the tool and the cheat sheet, plus an audit section with the az commands to list existing zones, VNet links and zone groups before creating more.

Cron / NCRONTAB Visualizer — an FAQ with the recipes people search for.

Sentinel tools, a dsregcmd explainer, and 14 enrolment error pages

2026-08-05

Three new tools and a new reference family.

Sentinel Analytics Rule Linter — paste an exported analytics rule (ARM template or REST JSON) and get the gaps flagged: a lookback shorter than the run interval, which silently drops everything between windows; a lookback exactly equal to it, which drops anything that arrives late; missing entity mappings; no MITRE tactics; alert-per-result with grouping off. These are the faults that make a rule look healthy in the portal while it quietly misses things.

Sentinel Cost Estimator — model the bill table by table across the Analytics, Basic and Auxiliary plans. It picks the cheapest commitment tier for your volume, shows every tier side by side, and is explicit about the two things people get wrong: commitment tiers only ever apply to Analytics data, and a tier bills its committed volume whether you fill it or not. Rates are editable — the shape of the answer is what transfers, not our default prices.

dsregcmd /status Explainer — paste the output and get every field explained plus a verdict: how the device is really joined, whether the user has a PRT, whether the device is still healthy in Entra ID, and what the registration diagnostics are actually saying. Both Sentinel tools and this one run entirely in your browser, as always.

The error database gains an Intune & Autopilot enrolment family — 14 pages covering the codes that come up during enrolment and device registration: 0x8007064C, 8018000A, 80180026, 0x80180014, 0x8018002B, 0x80180022, 0x801C03EA, 0x800705B4, 0x80070774, 0x801C0021, 0x801C001D, 0x801C03F2, 0x80CF0437 and DeviceCapReached.

Tools now live under a new Security & monitoring category as well.

Five new DNS tools

2026-07-21

The network category grows: Private Endpoint DNS Zones (pick your Azure services, get every privatelink zone they need), a DMARC Record Generator, a dig & nslookup Output Explainer, an Azure DNS Delegation Checker and a plain DNS Record Lookup.

The delegation checker and record lookup are the site's second and third server-assisted tools: browsers can't speak DNS, so the name you enter is resolved by our server via Cloudflare's public resolver. Both pages disclose exactly what is sent (the name and record type, nothing more — never stored). Everything else, as always, runs entirely in your browser.

There's also a new printable cheat sheet: Private endpoint DNS zones, the companion reference to the zone-picker tool.

And the DMARC/SPF/DKIM Analyzer learned to fetch records by domain — type a domain (plus a selector for DKIM) instead of pasting. The fetch uses the same disclosed server-side lookup; pasting still keeps everything local.

The Azure Toolbox launches

2026-07-18

First public release, with sixteen browser-based tools across certificates & PKI, network & auth, Entra & Graph, cost, and data utilities — plus the error-code reference database (60+ codes), a 46-term glossary, five printable cheat sheets and ten in-depth guides.

Everything runs client-side in your browser: no accounts, no cookies, no consent banners. The single exception is the SCEP Endpoint Tester, which uses a small server-side probe (clearly disclosed on the tool page).

An unhandled error has occurred. Reload 🗙